File name:

FluidSim.Spanish.Pack.by.CHEOPE.exe

Full analysis: https://app.any.run/tasks/e6a879dc-2c96-4f90-9095-e510dae0da14
Verdict: Malicious activity
Analysis date: October 17, 2024, 14:57:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
upx
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

00649B3FCEB4E5F79CD2F743F2C3A3F5

SHA1:

722F04ACEFDE755BA92525CD15C16EDBEAEE61AA

SHA256:

4F4BCC3DC430E11B3DF3A4ADC9CD5D2D1EA08403217B770C3B632E8212A86B19

SSDEEP:

49152:lgoFFhBkfnyJgp+H2WZCcvMCIHPHeBg2Ua5/R+5N9OUO6vAJWRrAiAbLawj4h8:ltFzkfnggQ2WZC4qPHeBg2NH+tRO6v6h

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Internet Settings

      • FluidSim.Spanish.Pack.by.CHEOPE.exe (PID: 3700)
    • Reads Internet Explorer settings

      • FluidSim.Spanish.Pack.by.CHEOPE.exe (PID: 3700)
    • Reads security settings of Internet Explorer

      • FluidSim.Spanish.Pack.by.CHEOPE.exe (PID: 3700)
    • Reads Microsoft Outlook installation path

      • FluidSim.Spanish.Pack.by.CHEOPE.exe (PID: 3700)
    • Executable content was dropped or overwritten

      • Festo FluidSIM v3.6.exe (PID: 2116)
      • INS3EA4.tmp (PID: 900)
    • Starts application with an unusual extension

      • Festo FluidSIM v3.6.exe (PID: 2116)
    • Process drops legitimate windows executable

      • INS3EA4.tmp (PID: 900)
    • Reads the Windows owner or organization settings

      • INS3EA4.tmp (PID: 900)
  • INFO

    • Checks supported languages

      • FluidSim.Spanish.Pack.by.CHEOPE.exe (PID: 3700)
      • Festo FluidSIM v3.6.exe (PID: 2116)
      • INS3EA4.tmp (PID: 900)
    • Checks proxy server information

      • FluidSim.Spanish.Pack.by.CHEOPE.exe (PID: 3700)
    • Reads the machine GUID from the registry

      • FluidSim.Spanish.Pack.by.CHEOPE.exe (PID: 3700)
    • UPX packer has been detected

      • FluidSim.Spanish.Pack.by.CHEOPE.exe (PID: 3700)
    • Reads the computer name

      • FluidSim.Spanish.Pack.by.CHEOPE.exe (PID: 3700)
      • INS3EA4.tmp (PID: 900)
    • Manual execution by a user

      • Festo FluidSIM v3.6.exe (PID: 2644)
      • Festo FluidSIM v3.6.exe (PID: 2116)
      • fl_sim_p.exe (PID: 3912)
    • Create files in a temporary directory

      • Festo FluidSIM v3.6.exe (PID: 2116)
      • INS3EA4.tmp (PID: 900)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | WinRAR Self Extracting archive (88.2)
.exe | UPX compressed Win32 Executable (4.6)
.exe | Win32 EXE Yoda's Crypter (4.5)
.dll | Win32 Dynamic Link Library (generic) (1.1)
.exe | Win32 Executable (generic) (0.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2004:12:26 15:34:28+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 5
CodeSize: 28672
InitializedDataSize: 8192
UninitializedDataSize: 110592
EntryPoint: 0x22a40
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
8
Malicious processes
0
Suspicious processes
3

Behavior graph

Click at the process to see the details
start THREAT fluidsim.spanish.pack.by.cheope.exe festo fluidsim v3.6.exe no specs festo fluidsim v3.6.exe ins3ea4.tmp fl_sim_p.exe no specs fl_sim_p.exe no specs fl_sim_p.exe no specs fluidsim.spanish.pack.by.cheope.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
900C:\Users\admin\AppData\Local\Temp\INS3EA4.tmp /SL3 $1001BE "C:\Users\admin\Desktop\Festo FluidSIM v3.6.exe" 5496743 5500157 61952 C:\Users\admin\AppData\Local\Temp\INS3EA4.tmp
Festo FluidSIM v3.6.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\ins3ea4.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1580"C:\Users\admin\AppData\Local\Temp\FluidSim.Spanish.Pack.by.CHEOPE.exe" C:\Users\admin\AppData\Local\Temp\FluidSim.Spanish.Pack.by.CHEOPE.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\fluidsim.spanish.pack.by.cheope.exe
c:\windows\system32\ntdll.dll
2116"C:\Users\admin\Desktop\Festo FluidSIM v3.6.exe" C:\Users\admin\Desktop\Festo FluidSIM v3.6.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\festo fluidsim v3.6.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2472"C:\Program Files\Festo Fluidsim\bin\fl_sim_p.exe"C:\Program Files\Festo Fluidsim\bin\fl_sim_p.exeINS3EA4.tmp
User:
admin
Company:
Art Systems Software GmbH, Festo Didactic GmbH & Co. KG
Integrity Level:
HIGH
Description:
FluidSIM - Fluidics Simulation Program
Exit code:
0
Version:
3, 6, 8, 0
Modules
Images
c:\program files\festo fluidsim\bin\fl_sim_p.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2644"C:\Users\admin\Desktop\Festo FluidSIM v3.6.exe" C:\Users\admin\Desktop\Festo FluidSIM v3.6.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\festo fluidsim v3.6.exe
c:\windows\system32\ntdll.dll
2872"C:\Program Files\Festo Fluidsim\bin\fl_sim_p.exe" C:\Program Files\Festo Fluidsim\bin\fl_sim_p.exeFluidSim.Spanish.Pack.by.CHEOPE.exe
User:
admin
Company:
Art Systems Software GmbH, Festo Didactic GmbH & Co. KG
Integrity Level:
HIGH
Description:
FluidSIM - Fluidics Simulation Program
Exit code:
0
Version:
3, 6, 8, 0
Modules
Images
c:\program files\festo fluidsim\bin\fl_sim_p.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3700"C:\Users\admin\AppData\Local\Temp\FluidSim.Spanish.Pack.by.CHEOPE.exe" C:\Users\admin\AppData\Local\Temp\FluidSim.Spanish.Pack.by.CHEOPE.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\fluidsim.spanish.pack.by.cheope.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
3912"C:\Program Files\Festo Fluidsim\bin\fl_sim_p.exe" C:\Program Files\Festo Fluidsim\bin\fl_sim_p.exeexplorer.exe
User:
admin
Company:
Art Systems Software GmbH, Festo Didactic GmbH & Co. KG
Integrity Level:
MEDIUM
Description:
FluidSIM - Fluidics Simulation Program
Version:
3, 6, 8, 0
Modules
Images
c:\program files\festo fluidsim\bin\fl_sim_p.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
1 219
Read events
1 186
Write events
25
Delete events
8

Modification events

(PID) Process:(3700) FluidSim.Spanish.Pack.by.CHEOPE.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3700) FluidSim.Spanish.Pack.by.CHEOPE.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(3700) FluidSim.Spanish.Pack.by.CHEOPE.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
(PID) Process:(3700) FluidSim.Spanish.Pack.by.CHEOPE.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoConfigURL
Value:
(PID) Process:(3700) FluidSim.Spanish.Pack.by.CHEOPE.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoDetect
Value:
(PID) Process:(3700) FluidSim.Spanish.Pack.by.CHEOPE.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005D010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3700) FluidSim.Spanish.Pack.by.CHEOPE.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3700) FluidSim.Spanish.Pack.by.CHEOPE.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3700) FluidSim.Spanish.Pack.by.CHEOPE.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3700) FluidSim.Spanish.Pack.by.CHEOPE.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
40
Suspicious files
471
Text files
484
Unknown types
14

Dropped files

PID
Process
Filename
Type
900INS3EA4.tmpC:\Program Files\Festo Fluidsim\is-APSVR.tmpexecutable
MD5:4430CC72B3A69E91F42043950461FBD1
SHA256:50C32B8B80073C71DDDB3997B147E9903E60AC6EE5C25DF237BFCE83CBBDA646
900INS3EA4.tmpC:\Program Files\Festo Fluidsim\bin\is-IG25F.tmpexecutable
MD5:5FEDD5848B7378DA05692E0E4D3E8F18
SHA256:477A2ADE1F1E0C1120A3ABC40A840612FFBD3D182BE65EB0711849112F4EA025
900INS3EA4.tmpC:\Program Files\Festo Fluidsim\bin\is-8PAE6.tmpexecutable
MD5:C929E9E8275A2F88CDE936948034E7DF
SHA256:7B8BAF59C59A3B552F20C30CB3BD82E3EED88934AD9CB0E37F6E8856DF2FB91F
900INS3EA4.tmpC:\Program Files\Festo Fluidsim\bin\is-RCL4M.tmpexecutable
MD5:929F6F961FB3EA09FC6007C30E8CACCB
SHA256:FC11D1637A4CA4560461CD0B434CC2E98D5B96770715D96EC9017BA884E056A0
900INS3EA4.tmpC:\Program Files\Festo Fluidsim\bin\ad_dde.dllexecutable
MD5:26CAB8629E5DCFA73DF88C2252BE1E77
SHA256:18B79556AF2B999BBD00772499C63B5C70F44233506B77F7916432895589A93A
900INS3EA4.tmpC:\Program Files\Festo Fluidsim\bin\ad_dxf.dllexecutable
MD5:F0AC29A29489586A11174295D1049A72
SHA256:CBA710C7809A43158A4ADB8C67FBAB5F81D896BF82875363EF70A4018A5CF394
900INS3EA4.tmpC:\Program Files\Festo Fluidsim\bin\ad_io.dllexecutable
MD5:5FEDD5848B7378DA05692E0E4D3E8F18
SHA256:477A2ADE1F1E0C1120A3ABC40A840612FFBD3D182BE65EB0711849112F4EA025
900INS3EA4.tmpC:\Program Files\Festo Fluidsim\unins000.exeexecutable
MD5:4430CC72B3A69E91F42043950461FBD1
SHA256:50C32B8B80073C71DDDB3997B147E9903E60AC6EE5C25DF237BFCE83CBBDA646
900INS3EA4.tmpC:\Program Files\Festo Fluidsim\aq\acp.kbbinary
MD5:EEFFC25435685E5AC19E23EE1843B717
SHA256:E9826CC3FE2F07F20087056B35E7862E4F13B6C4C354EC926524F02FB5BF02BF
900INS3EA4.tmpC:\Program Files\Festo Fluidsim\bin\ad_jpg.dllexecutable
MD5:F2C3502D093412E7E44B09A8FE747F64
SHA256:0EE25CFFC99E2019C6AFBA12378C636D8CEC99E1929764B30AA4EB9E861F3D5B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
239.255.255.250:3702
whitelisted
224.0.0.252:5355
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.142
whitelisted

Threats

No threats detected
No debug info